pptx

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run to execute external binaries for document processing tasks. These include soffice (LibreOffice) for PDF conversion and validation, pdftoppm (Poppler) for thumbnail generation, and git for XML content comparison. These are legitimate uses of platform tools to achieve the skill's primary purpose.
  • [EXTERNAL_DOWNLOADS]: The skill documentation outlines dependencies on several well-known and trusted packages from official registries, such as markitdown, pptxgenjs, playwright, and sharp.
  • [SAFE_PRACTICE]: The skill uses defusedxml for XML parsing in several scripts, which provides protection against XML external entity (XXE) attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 07:36 AM
Security Audit — agent-trust-hub — pptx